GitHub shipped gh skill on April 16. The command discovers, installs, manages, and publishes agent skills. That matches how I already use GitHub for a private skills repository.

Each skill in that repository is a Markdown file with a trigger description and a workflow. Git records the history. Tests catch broken references and style drift. Pull requests provide the review boundary. Installation happens by path. None of those controls is new, which is useful: agent instructions can use the same machinery as code.

GitHub's enterprise governance guidance for agents extends that model with protected instruction files, a role for skill curation, and audit-log streaming. Those controls are still emerging, and a Markdown file is not a security boundary. But it is reviewable. That is a better starting point than instructions copied between laptops with no owner or history.

The practical gain is smaller and clearer than a new governance category. I can change one skill, review the diff, run the tests, and install the same version everywhere I use it. gh skill makes that workflow easier to distribute.